The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.4.1's own posts.
We have discovered 24,353 live websites that are affected by CVE-2026-18366.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 24,353 live websites (69% of Events Manager for WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 30 versions ( 28% of all versions) |
| 6,735 websites | |
| 5,876 websites | |
| 1,765 websites | |
| 1,425 websites | |
| 1,320 websites | |
| 779 websites | |
| 709 websites | |
| 616 websites | |
| 543 websites | |
| 389 websites |
| .com | 5,359 websites |
| .de | 4,745 websites |
| .org | 3,791 websites |
| .nl | 1,366 websites |
| .fr | 972 websites |
| .ch | 681 websites |
| .it | 542 websites |
| .co.uk | 530 websites |
| .net | 470 websites |
| .at | 413 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.org | **,*** | ||
| *********.*******.org | **,*** | ||
| **************.gov | **,*** | ||
| ********.org | **,*** | ||
| *****.br | **,*** | ||
| ****.org | **,*** | ||
| *****.org | **,*** | ||
| ****.org | **,*** | ||
| **********************.org | **,*** | ||
| *****************.com | **,*** |
FAQ